Allied Intelligence — 2026-07-09

CSE Annual Report 2025-26 Discloses 3216 Cyber Incidents Responded to and Disruption of 10 Ransomware Groups Targeting Canada

BLUFOttawa's shift from isolated takedowns to concurrent disruption of 10 ransomware groups marks Canada's normalization of offensive cyber operations as a standing security function.

In its 2025-2026 Annual Report released June 30, Canada's Communications Security Establishment said its Canadian Centre for Cyber Security responded to more than 3,216 cyber incidents affecting federal institutions and critical infrastructure, held 522 engagements with infrastructure partners, and conducted 13 briefings on quantum-computing threats to cryptography 1. CSE said intelligence support enabled investigations into ransomware-as-a-service operations responsible for more than 25 incidents against transportation, healthcare, pharmaceutical and business sectors, and that the agency took concurrent action against 10 significant ransomware groups this year, using signals intelligence to render one prolific RaaS group's infrastructure inoperable and delete stolen data the group had advertised for sale on the dark web 1. The Record reported CSE's hacking operations targeted three criminal groups in 2025: an extremist organization whose recruitment credibility CSE undermined, a network trafficking fentanyl precursor chemicals, and a ransomware gang, a narrower framing than the report's broader ransomware-group disruption figures 2. CSE Chief Caroline Xavier and Defence Minister David McGuinty both stated in the report that state-sponsored actors are increasingly conducting disruptive cyber activity alongside espionage 1.

Analysis
CSE's disclosure of coordinated action against 10 ransomware groups, rather than isolated takedowns, indicates offensive cyber operations are becoming a standing complement to defensive incident response. The gap between that aggregate figure and The Record's narrower three-target account, the only independent secondary reporting against CSE's own primary release, suggests Ottawa is calibrating what it publicly attributes to manage diplomatic exposure while still signaling capability. The aggregate may also reflect joint operations with law enforcement rather than ten unilateral CSE actions, a distinction the report leaves unresolved. Subsequent reporting narrowed that aggregate to identifiable categories, drug trafficking and extremist-network targets, for the first time. Thirteen quantum-cryptography briefings alongside 3,216 incident responses indicate CSE now treats post-quantum migration as an operational priority, with federal institutions and infrastructure operators bearing the transition burden.
3 sources
  1. Canada's CSE report details rising cyber threats, ransomware investigations, critical infrastructure protection efforts - Industrial Cyber
  2. Canadian spy agency reports hacking three criminal groups in 2025 - The Record (Recorded Future News)
  3. Communications Security Establishment Canada releases its 2025-2026 Annual Report - Communications Security Establishment Canada / Canada.ca

View in full brief →

UNCLASSIFIED // OPEN SOURCE